CVE Database
/

CVE-2016-5095

Back to search

CVE-2016-5095

Published: Aug 7, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

Integer overflow in the php_escape_html_entities_ex function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from a FILTER_SANITIZE_FULL_SPECIAL_CHARS filter_var call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-5094.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-3602
vendor-advisory
x_refsource_DEBIAN
92144
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now